/
DirectorySecurity AdvisoriesPricing
Sign In
Security Advisories

CVE-2023-1428

Published

Last updated

NVD

https://nvd.nist.gov/vuln/detail/CVE-2023-1428

Severity

Unknown

Description

There exists an vulnerability causing an abort() to be called in gRPC.  The following headers cause gRPC's C++ implementation to abort() when called via http2:

te: x (x != trailers)

:scheme: x (x != http, https)

grpclb_client_stats: x (x == anything)

On top of sending one of those headers, a later header must be sent that gets the total header size past 8KB. We recommend upgrading past git commit 2485fa94bd8a723e5c977d55a3ce10b301b437f8 or v1.53 and above.

References

  • https://images.chainguard.dev/security/CGA-5c89-h92g-qh4v

Affected packages


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Products

Chainguard ContainersChainguard LibrariesChainguard VMs